Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

Hardware Worth $1.9 Million Stolen in Russia’s Crypto Mining Capital
Hardware Worth $1.9 Million Stolen in Russia’s Crypto Mining Capital Russian law enforcement is looking into the alleged theft of mining hardware valued at around $1.9 million. T
DeFi TVL breaches $100B, MakerDAO readies DAI ‘Endgame:’ Finance Redefined
Prashant Jha4 hours agoDeFi TVL breaches $100B, MakerDAO readies DAI ‘Endgame:’ Finance RedefinedThe total value locked in DeFi protocols has breached $110 billion — but it’s still short of the $189 billion all-t
Mike Bloomberg’s 2020 Finance Policy Proposes Strict Bitcoin Regulations
Mike Bloomberg"s 2020 Finance Policy Proposes Strict Bitcoin Regulations The 2020 U.S. Presidential candidate Michael Bloomberg addressed the subject of cryptocurrencies and init
Survey: Proportion of South African Crypto Holders Grows to 11.3%, 56% of Crypto Owners Hold Bitcoin
Survey: Proportion of South African Crypto Holders Grows to 11.3%, 56% of Crypto Owners Hold Bitcoin The number of surveyed South Africans that own crypto grew marginally from 10.3
Helen Partz10 hours agoNFT startup Rario loses founders after $120M funding last year: ReportAs part of the restructuring efforts at Rario, a number of roles are also being eliminated, according to a report.1019 Total vi
Crypto market stumbles amid arrest of Samourai Wallet founders
Ciaran Lyons5 hours agoCrypto market stumbles amid arrest of Samourai Wallet foundersThe crypto market saw extra turbulence after Samourai Wallet’s CEO and chief technology officer faced legal action from the U.S. DOJ.
Web3 gaming is ‘rocket ship’ ready to blast off, say industry execs
Jonathan DeYoung12 hours agoWeb3 gaming is ‘rocket ship’ ready to blast off, say industry execsThe Decentralize with Cointelegraph podcast interviews gaming executives from five Web3 projects to learn everything ther
Wormhole Network Launches Ethereum Solana Bridge, Solana AMM Saber Surpasses $4 Billion TVL
Wormhole Network Launches Ethereum Solana Bridge, Solana AMM Saber Surpasses $4 Billion TVL On September 17, 2021, Solana protocol fans were introduced to the launch of the Wormhol
Helen Partz10 hours agoCaitlin Long’s Custodia Bank launches Bitcoin custody platformCustodia Bank’s launch of Bitcoin custody follows a series of regulatory challenges the firm faced earlier this year.2295 Total vie
Notorious ‘jaredfromsubway’ MEV bot returns with new attacks
Martin Young5 hours agoNotorious ‘jaredfromsubway’ MEV bot returns with new attacksThe “jaredfromsubway.eth” MEV bot appears to have relaunched with a better arsenal for carrying out attacks.2364 Total views3 Tot
MicroStrategy stock spikes over 20% as BTC price continues skyward
Derek Andersen5 hours agoMicroStrategy stock spikes over 20% as BTC price continues skywardShort-sellers may be generating some of the gain, but MicroStrategy’s fundamentals are strong.4179 Total views32 Total sharesLi
Tokenized Gold Market Caps Grew Significantly Last Month as Fresh Demand Drives Premiums
Tokenized Gold Market Caps Grew Significantly Last Month as Fresh Demand Drives Premiums While gold tapped an all-time high (ATH) this year surpassing $2K per ounce, the top tokeni